Static analysis of machine code for supply-chain risk management
Paul Anderson, Alexey A. Loginov · 2013
This paper discusses the product-oriented approach to software supply-chain risk management: a determination of the trustworthiness of software applications, or the relative trustworthiness among a set of software applications, based on automated analysis and inspection of their actual binary machine codes. The system, named CodeSonar™ for binaries, is a static-analysis tool that can find security vulnerabilities in stripped and optimized executables. It is built as an extension to a successful product for analyzing source code, so it is also capable of analyzing source and machine code simultaneously. It can find defects such as buffer overruns, null pointer dereferences, resource leaks, and uninitialized variables.